HEAVYGRAM Malware Uses Telegram as a Command Center in Handala Hack Campaign
Group-IB has uncovered new HEAVYGRAM samples linked with moderate confidence to Handala Hack, revealing a Windows surveillance backdoor that uses Telegram for command-and-control, persistence and data theft.
Xcademia Team
Xcademia Research Team

A newly detailed Windows malware campaign is showing how legitimate messaging platforms can be repurposed as infrastructure for surveillance and remote control.
Group-IB Threat Intelligence has analyzed previously undocumented samples of HEAVYGRAM and CRUDEEXCLUDE, linking the activity with moderate confidence to Handala Hack, an Iran-linked threat actor persona. According to Group-IB, HEAVYGRAM has been used since the fall of 2023 against Iranian dissidents, journalists and people viewed as opponents of the Iranian government.
The research describes a multi-stage infection chain that combines social engineering, fake legitimate applications, defense evasion, persistent access and Telegram-based command-and-control.
The findings build on U.S. government disclosures made earlier in 2026, including an FBI FLASH report and a U.S. Department of Justice affidavit that described Heavygram-related activity.
What Is HEAVYGRAM?
HEAVYGRAM is a Windows backdoor and persistent implant designed to give operators remote access to compromised systems.
According to Group-IB, the malware can support remote command execution, system and network discovery, screenshot collection, data exfiltration, execution of additional payloads and persistence. It can also interact with Telegram data stored on an infected system.
The Hacker News reported that the malware can also collect browser-related information, access saved passwords, interact with Telegram and WhatsApp data, upload and download files, activate the microphone and remove files from compromised systems.
Group-IB identified 29 additional samples, including loaders and payloads associated with the malware family. Its analysis also found that operators used networks of Telegram bots, accounts and groups as part of the command-and-control infrastructure.
Why Telegram Matters
The most notable aspect of HEAVYGRAM is not simply that it communicates over the internet. It uses Telegram as part of its operational infrastructure.
Instead of depending entirely on a conventional attacker-controlled command server, the malware can communicate through Telegram's bot infrastructure. This gives operators a platform through which they can send instructions and receive information from compromised systems.
Group-IB identified different infrastructure configurations, including setups involving a single Telegram bot and group, as well as arrangements where different bots were used for check-ins, logging and retrieving additional stages.
This approach demonstrates how threat actors can abuse widely used online services as part of malware operations.

How the Attack Begins
The reported attacks commonly begin with social engineering.
According to Group-IB and The Hacker News, targets were contacted through messaging platforms and encouraged to execute files presented as legitimate applications or useful software. Telegram was specifically documented in the public disclosures, while The Hacker News reported that similar approaches could involve WhatsApp and Instagram.
The malware was disguised as software that a target might reasonably trust.
Observed lures included applications masquerading as:
Telegram
KeePass
Pictory
Other legitimate-looking Windows programs
The objective was to persuade the target to execute the initial file, which then enabled subsequent stages of the infection.
This is an important part of the campaign because the first stage relies on user trust rather than simply exploiting a software vulnerability.
A malicious file can appear much less suspicious when it is presented as a familiar application or delivered by someone the victim believes they know.
Four Observed Delivery Methods
Group-IB identified four primary delivery approaches associated with HEAVYGRAM:
WSF and VBS scripts
VBScript and HTML Application files
Executables containing embedded archives
CRUDEEXCLUDE samples containing embedded archives
These methods provide different routes for delivering the persistent implant to the Windows system.
The multi-stage design also means that the initial file does not necessarily represent the full malware payload. Instead, it can prepare the environment and deliver later components.
CRUDEEXCLUDE: Preparing the Environment
Alongside HEAVYGRAM, Group-IB analyzed malware samples associated with CRUDEEXCLUDE.
CRUDEEXCLUDE is a Windows utility that can masquerade as legitimate software while modifying Microsoft Defender exclusion settings. This behavior can prevent security scanning from being applied to selected directories used during the malware deployment process.
The Hacker News described CRUDEEXCLUDE as a Delphi-based utility used to prepare the system for subsequent stages such as HEAVYGRAM. It was first observed in the reported activity in 2024 and has been associated with fake legitimate applications.
This creates a two-part problem for defenders.
The first challenge is getting the victim to run the fake application. The second is detecting changes made after execution that can reduce the effectiveness of endpoint protection.

What HEAVYGRAM Can Do
Once established on a Windows system, HEAVYGRAM provides operators with several capabilities.
Group-IB's analysis identifies functions associated with:
Remote command execution
System and network information discovery
Process discovery
Screenshot capture
File collection and exfiltration
Execution of additional payloads
Persistence through Windows Registry autorun mechanisms
Collection of Telegram Desktop data
DLL side-loading
File cleanup
The Hacker News additionally reported capabilities involving browser data, saved passwords, microphone access and WhatsApp data.
The combination means HEAVYGRAM is not limited to collecting one type of information.
It can potentially provide operators with visibility into the compromised system while also maintaining access and supporting additional malware components.
Telegram Becomes the Command-and-Control Layer
HEAVYGRAM's use of Telegram is central to the research.
The implant communicates with Telegram bots to receive instructions and return information. Group-IB found multiple infrastructure configurations, including setups where one bot handled communication and another was used for additional operational functions.
The malware also sends an initial beacon containing information about the compromised computer. A background process can subsequently send periodic health messages to indicate that the implant remains active. Group-IB reported a 24-hour heartbeat mechanism in its analysis.
From a defensive perspective, this creates another challenge.
Security teams may need to investigate suspicious Telegram-related network activity alongside conventional endpoint indicators rather than treating messaging applications only as productivity or communication tools.
Persistence After Reboots
HEAVYGRAM also incorporates persistence mechanisms.
According to the research, the malware can use Windows Registry autorun locations to ensure components are launched again after system restarts.
Group-IB recommends defenders audit Windows autorun Registry keys for unauthorized entries when investigating systems associated with the campaign.
Persistence matters because removing an obvious malicious file does not necessarily eliminate the entire infection chain.
A complete investigation needs to consider loaders, secondary payloads, persistence mechanisms, configuration changes and command-and-control activity.

Who Was Targeted?
Public disclosures cited by Group-IB indicate that the malware has been used against people of interest to the operators, including Iranian dissidents and journalists.
Group-IB also referenced a U.S. Department of Justice affidavit involving a journalist working for a UK-based Farsi-language news organization. According to the affidavit described by Group-IB, the victim was contacted through Telegram and executed the first-stage malware, after which additional components were downloaded.
The FBI has separately described activity involving Iranian dissidents, journalists opposed to the Iranian government and other opposition groups. The agency's March 2026 advisory described the use of Telegram-based command-and-control infrastructure in malware campaigns targeting identified individuals.
The targeting described in these reports is therefore more focused than indiscriminate mass malware distribution.
Connection to Handala Hack
Group-IB attributes HEAVYGRAM to Handala Hack with moderate confidence.
That assessment is based on several pieces of evidence, including a U.S. government affidavit linking Heavygram activity with Handala Hack and malware indicators that were later corroborated by the FBI's reporting. Group-IB also identified overlaps between HEAVYGRAM capabilities and previously reported intrusions involving compromised Telegram accounts.
The Hacker News reported that Handala Hack is assessed as an online persona associated with Void Manticore, also tracked under other names, and described as affiliated with Iran's Ministry of Intelligence and Security.
These are attribution assessments rather than independently established facts about every HEAVYGRAM sample. Group-IB specifically uses the qualification moderate confidence, which is important when interpreting the findings.
Government Reporting Adds Context
The HEAVYGRAM research follows earlier U.S. government disclosures.
On March 19, 2026, the U.S. Department of Justice announced the seizure of four domains it associated with Iran's Ministry of Intelligence and Security. Group-IB's investigation notes that the accompanying affidavit contained references to Heavygram and related files.
The FBI's March 2026 FLASH report described a malware campaign in which stage-one files masqueraded as applications such as Pictory, KeePass and Telegram before establishing a persistent implant that communicated through Telegram.
The FBI later expanded its reporting on HEAVYGRAM in September 2026, according to Group-IB.
The UK's National Cyber Security Centre tracks the same malware family under the name CHOSEN BRICK, according to The Hacker News.
Different naming conventions across security organizations are common in threat intelligence. They can make cross-referencing incidents more difficult, which is why malware capabilities, indicators and infrastructure relationships are often more useful than a single malware name.
What Security Teams Can Learn From the Campaign
The HEAVYGRAM activity highlights several defensive areas that organizations can monitor.
1. Watch for suspicious software delivery
Users should obtain applications from official vendor sources and avoid software installers delivered unexpectedly through messaging platforms.
Group-IB specifically recommends using trusted official sources and verifying contacts through another trusted communication channel.
2. Monitor security configuration changes
Unexpected Microsoft Defender exclusion changes deserve investigation, particularly when they involve unusual directories or newly created application paths.
3. Review persistence mechanisms
Security teams investigating a potentially compromised Windows system should review Registry autorun locations and other persistence mechanisms.
4. Monitor unusual messaging-platform activity
Because HEAVYGRAM uses Telegram as part of its C2 infrastructure, defenders should consider whether unexpected Telegram-related network or endpoint activity corresponds with known indicators from the campaign.
5. Investigate multi-stage infections
An initial malicious file may only represent one component of the infection.
Incident response should consider the entire chain, including the initial lure, loader, security configuration changes, persistent implant, additional payloads and command-and-control activity.
6. Keep endpoint software updated
Group-IB recommends maintaining current operating system updates and security patches and educating users about phishing and suspicious files.

Why the HEAVYGRAM Research Matters
The HEAVYGRAM investigation illustrates how modern malware operations can combine familiar social engineering techniques with legitimate online infrastructure.
The technical complexity is distributed across several stages rather than concentrated in one executable. A victim may first encounter a convincing application, while later components handle defense evasion, persistence, surveillance and communication with operators.
The use of Telegram also demonstrates the broader security challenge created when attackers abuse legitimate services. Defenders cannot necessarily rely on the presence of a well-known platform as evidence that an activity is legitimate.
For enterprises, the development could reinforce the value of layered security controls that combine endpoint monitoring, user awareness, threat intelligence, network analysis and incident response.
This is an analysis of the defensive implications of the reported activity. The announcement does not provide enough information to quantify how widespread the campaign is or how many organizations or individuals have been affected.
Conclusion
Group-IB's investigation adds new technical detail to the public understanding of HEAVYGRAM, CRUDEEXCLUDE and their reported connection to Handala Hack.
The research describes a multi-stage Windows infection chain involving social engineering, application masquerading, Microsoft Defender exclusion abuse, persistent access and Telegram-based command-and-control.
The most notable feature is the integration of Telegram into the malware's operational workflow. The platform is used to support communication between compromised systems and operators, while HEAVYGRAM provides capabilities for remote commands, surveillance, data collection and persistence.
Group-IB's attribution remains moderate confidence, and the research should be read alongside the FBI and U.S. Department of Justice disclosures that provide additional context.
For security teams, the case reinforces a practical lesson: monitoring should extend beyond obvious malicious files. Suspicious application delivery, endpoint configuration changes, unexpected persistence and unusual activity involving trusted online services can all form part of the same attack chain.
Additional details were not disclosed in the announcement about the full number of victims or the total impact of the campaign.
Source: Group-IB Threat Intelligence
About the Author